6.3

CVSS4.0

CVE-2025-46346 - YesWiki Vulnerable to Stored XSS in Comments

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, a stored cross-site scripting (XSS) vulnerability was discovered in the applicationโ€™s comments feature. This issue allows a malicious actor to inject JavaScript payloads that are stored and later executed in the browser of any user viโ€ฆ

๐Ÿ“… Published: April 29, 2025, 3:36 p.m. ๐Ÿ”„ Last Modified: May 9, 2025, 1:53 p.m.

4.8

CVSS4.0

CVE-2025-4069 - code-projects Product Management System add_item stack-based overflow

A vulnerability, which was classified as critical, has been found in code-projects Product Management System 1.0. Affected by this issue is the function add_item. The manipulation of the argument st.productname leads to stack-based buffer overflow. An attack has to be approached locally. The exploiโ€ฆ

๐Ÿ“… Published: April 29, 2025, 3:31 p.m. ๐Ÿ”„ Last Modified: May 28, 2025, 5:26 p.m.

4.8

CVSS4.0

CVE-2025-4068 - code-projects Simple Movie Ticket Booking System changeprize stack-based overflow

A vulnerability classified as critical was found in code-projects Simple Movie Ticket Booking System 1.0. Affected by this vulnerability is the function changeprize. The manipulation of the argument prize leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit hโ€ฆ

๐Ÿ“… Published: April 29, 2025, 3:31 p.m. ๐Ÿ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

6.9

CVSS4.0

CVE-2025-4067 - ScriptAndTools Online-Travling-System viewpackage.php access control

A vulnerability classified as critical has been found in ScriptAndTools Online-Travling-System 1.0. Affected is an unknown function of the file /admin/viewpackage.php. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed toโ€ฆ

๐Ÿ“… Published: April 29, 2025, 3 p.m. ๐Ÿ”„ Last Modified: May 12, 2025, 7:35 p.m.

6.9

CVSS4.0

CVE-2025-4066 - ScriptAndTools Online-Travling-System addpackage.php access control

A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/addpackage.php. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosโ€ฆ

๐Ÿ“… Published: April 29, 2025, 2:31 p.m. ๐Ÿ”„ Last Modified: May 12, 2025, 7:35 p.m.

6.9

CVSS4.0

CVE-2025-4065 - ScriptAndTools Online-Travling-System addadvertisement.php access control

A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/addadvertisement.php. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been dโ€ฆ

๐Ÿ“… Published: April 29, 2025, 2:31 p.m. ๐Ÿ”„ Last Modified: May 12, 2025, 7:35 p.m.

6.9

CVSS4.0

CVE-2025-4064 - ScriptAndTools Online-Travling-System viewenquiry.php access control

A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/viewenquiry.php. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclโ€ฆ

๐Ÿ“… Published: April 29, 2025, 2 p.m. ๐Ÿ”„ Last Modified: May 9, 2025, 7:33 p.m.

1

CVSS4.0

CVE-2025-3301 - DPA Countermeasures Unavailable for Certain Cryptographic Operations on Series 2 Devices

DPA countermeasures are unavailable for ECDH key agreement and EdDSA signing operations on Curve25519 and Curve448 on all Series 2 modules and SoCs due to a lack of hardware and software support. A successful DPA attack may result in exposure of confidential information. The best practice is to useโ€ฆ

๐Ÿ“… Published: April 29, 2025, 1:47 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-4063 - code-projects Student Information Management System cancel stack-based overflow

A vulnerability was found in code-projects Student Information Management System 1.0 and classified as critical. Affected by this issue is the function cancel. The manipulation of the argument first_name/last_name leads to stack-based buffer overflow. The attack needs to be approached locally. The โ€ฆ

๐Ÿ“… Published: April 29, 2025, 1:31 p.m. ๐Ÿ”„ Last Modified: May 12, 2025, 2:09 p.m.

4.8

CVSS4.0

CVE-2025-4062 - code-projects Theater Seat Booking System cancel stack-based overflow

A vulnerability has been found in code-projects Theater Seat Booking System 1.0 and classified as critical. Affected by this vulnerability is the function cancel. The manipulation of the argument cancelcustomername leads to stack-based buffer overflow. It is possible to launch the attack on the locโ€ฆ

๐Ÿ“… Published: April 29, 2025, 1:31 p.m. ๐Ÿ”„ Last Modified: May 9, 2025, 7:34 p.m.
Total resulsts: 346179
Page 5335 of 34,618
ยซ previous page ยป next page
Filters